WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,851–1,900 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 38 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High RVCFDI para Woocommerce Plugin rvcfdi-para-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.1.8 CVE-2025-69386 Patchstack
7.1 High Timeline Event History Plugin timeline-event-history Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2 CVE-2025-69384 Patchstack
7.5 High WP shop Plugin wpshop Local File Inclusion No login needed ≤ 2.6.1 CVE-2025-69383 Patchstack
7.1 High WooCommerce Bulk Product Editor Plugin woocommerce-quick-product-editor Broken Access Control ≤ 3.0 CVE-2025-69381 Patchstack
7.5 High Upload Files Anywhere Plugin wp-upload-files-anywhere Path Traversal Arbitrary File Download No login needed ≤ 2.8 CVE-2025-69380 Patchstack
8.6 High Upload Files Anywhere Plugin wp-upload-files-anywhere Arbitrary File Deletion No login needed ≤ 2.8 CVE-2025-69379 Patchstack
7.2 High Product Filter for WooCommerce Plugin prdctfltr Privilege Escalation ≤ 9.1.2 CVE-2025-69378 Patchstack
7.7 High User Extra Fields Plugin wp-user-extra-fields Arbitrary File Deletion ≤ 17.0 CVE-2025-69377 Patchstack
8.6 High User Extra Fields Plugin wp-user-extra-fields Arbitrary File Deletion No login needed ≤ 17.0 Fixed in 17.1 CVE-2025-69376 Patchstack
8.1 High Portfolio Builder Plugin swp-portfolio Local File Inclusion No login needed ≤ 1.2.5 CVE-2025-69375 Patchstack
8.1 High Eleblog – Elementor Blog And Magazine Addons Plugin ele-blog Local File Inclusion Elementor Blog And Magazine Addons plugin <= 2.0.3 - Local File Inclusion No login needed ≤ 2.0.3 CVE-2025-69374 Patchstack
7.5 High VidoRev Theme vidorev Local File Inclusion ≤ 2.9.9.9.9.9.7 CVE-2025-69373 Patchstack
7.1 High SOHO - Photography Theme soho Cross-Site Scripting Photography WordPress Theme theme <= 3.0.3 - Cross Site Scripting (XSS) No login needed ≤ 3.0.3 CVE-2025-69368 Patchstack
7.1 High Oyster - Photography Theme oyster Cross-Site Scripting Photography WordPress Theme theme <= 4.4.3 - Cross Site Scripting (XSS) No login needed ≤ 4.4.3 CVE-2025-69367 Patchstack
7.1 High Prestige Theme prestige Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 Fixed in 1.4.1 CVE-2025-69330 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.9 Fixed in 2.6.0 CVE-2025-69328 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.1.7 Fixed in 9.1.8 CVE-2025-69326 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting No login needed ≤ 9.1.7 Fixed in 9.1.8 CVE-2025-69324 Patchstack
7.1 High Slimstat Analytics Plugin wp-slimstat Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.2 Fixed in 5.3.3 CVE-2025-69323 Patchstack
8.1 High PeakShops Theme peakshops Local File Inclusion No login needed ≤ 1.5.9 Fixed in 1.5.9 CVE-2025-69322 Patchstack
7.5 High ModelTheme Framework Plugin modeltheme-framework Broken Access Control No login needed ≤ 2.0.0 Fixed in 2.0.0 CVE-2025-69303 Patchstack
7.1 High DesignThemes Core Features Plugin designthemes-core-features Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-69302 Patchstack
7.2 High Oxygen Theme oxygen Server-Side Request Forgery No login needed ≤ 6.0.8 CVE-2025-69299 Patchstack
7.5 High Gauge Theme gauge Broken Access Control No login needed ≤ 6.56.4 CVE-2025-69298 Patchstack
7.5 High Aardvark Plugin aardvark-plugin Broken Access Control No login needed ≤ 2.19 CVE-2025-69297 Patchstack
7.1 High Aardvark Theme aardvark Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.6.3 CVE-2025-69296 Patchstack
8.8 High PeakShops Theme peakshops PHP Object Injection ≤ 1.5.9 CVE-2025-69294 Patchstack
8.6 High New User Approve Plugin new-user-approve Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-69063 Patchstack
7.1 High Simple Archive Generator Plugin simple-archive-generator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2 CVE-2025-68880 Patchstack
7.1 High iContact for Gravity Forms Plugin gravity-forms-icontact Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-68863 Patchstack
7.7 High Woo File Dropzone Plugin woo-file-dropzone Arbitrary File Deletion ≤ 1.1.7 CVE-2025-68862 Patchstack
7.1 High Mopinion Feedback Form Plugin mopinion-feedback-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-68856 Patchstack
7.1 High ID Arrays Plugin id-arrays Cross-Site Scripting POST-Based Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.2 CVE-2025-68854 Patchstack
8.8 High Contact Manager Plugin contact-manager PHP Object Injection No login needed ≤ 9.1.1 CVE-2025-68853 Patchstack
7.1 High Court Reservation Plugin court-reservation Cross-Site Scripting No login needed ≤ 1.10.13 CVE-2025-68852 Patchstack
7.1 High amr cron manager Plugin amr-cron-manager Cross-Site Scripting Reflecte dCross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-68848 Patchstack
7.1 High iSape Plugin isape Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.72 CVE-2025-68847 Patchstack
7.1 High Asynchronous Javascript Plugin asynchronous-javascript Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.5 CVE-2025-68846 Patchstack
7.1 High eDS Responsive Menu Plugin eds-responsive-menu Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-68845 Patchstack
7.1 High Membee Login Plugin membees-member-login-widget Cross-Site Scripting No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-68844 Patchstack
7.1 High FeedWordPress Advanced Filters Plugin faf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.2 CVE-2025-68843 Patchstack
7.1 High Widget Logic Visual Plugin widget-logic-visual Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.52 CVE-2025-68842 Patchstack
7.5 High TopperPack – Complete Elementor Addons, Theme & CPT Builder Plugin topper-pack Local File Inclusion Complete Elementor Addons, theme & CPT Builder plugin <= 1.2.1 - Local File Inclusion No login needed ≤ 1.2.1 CVE-2025-68841 Patchstack
7.5 High Sync Master Sheet – Product Sync with Google Sheet for WooCommerce Plugin product-sync-master-sheet Broken Access Control Product Sync with Google Sheet for WooCommerce plugin <= 1.1.3 - Broken Access Control No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-68834 Patchstack
7.5 High WooCommerce Coming Soon Product with Countdown Plugin woo-coming-soon-product Local File Inclusion ≤ 5.0 Fixed in 5.1 CVE-2025-68552 Patchstack
8.1 High Nika Plugin nika Local File Inclusion No login needed ≤ 1.2.14 Fixed in 1.2.15 CVE-2025-68545 Patchstack
8.1 High Diza Theme diza Local File Inclusion No login needed ≤ 1.3.15 Fixed in 1.3.16 CVE-2025-68543 Patchstack
8.1 High Fana Plugin fana Local File Inclusion No login needed ≤ 1.1.35 Fixed in 1.1.36 CVE-2025-68539 Patchstack
8.1 High Zota Plugin zota Local File Inclusion No login needed ≤ 1.3.14 Fixed in 1.3.15 CVE-2025-68536 Patchstack
8.8 High ModelTheme Addons for WPBakery and Elementor Plugin modeltheme-addons-for-wpbakery PHP Object Injection ≤ 1.5.6 Fixed in 1.5.6 CVE-2025-68531 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only